API keys
An API key is the secret token your application uses to authenticate to the RestFlags public API. This page covers creating, scoping, restricting and rotating keys.
Key prefixes
Every key carries a visible prefix so you can tell at a glance what it is:
rf_live_…— a production key.rf_test_…— a development or staging key.
Only the prefix and last four characters are ever shown after creation. RestFlags stores a hash of the secret, never the secret itself.
Environments
Each key is bound to one environment — development, staging or production. A key can only evaluate flags in its own environment. If a request specifies a different environment than the key allows, it is rejected. This stops a test key from ever reading production state.
Scopes
A key's scope controls what it may do:
| Scope | Allows |
|---|---|
| Read only | Evaluate flags and read flag definitions. |
| Read / write | Everything above, plus changing flag state. |
| Admin | Everything above, plus managing API keys. |
Grant the narrowest scope that works. Most application code only needs Read only — it evaluates flags, nothing more.
IP allowlist
You can optionally restrict a key to a set of IP ranges, given as CIDR blocks
(for example 203.0.113.0/24). When the allowlist is set, requests from any
other address are rejected. Leave it empty to allow all addresses.
Creating a key
- Open API keys in the sidebar and click Create new key.
- Enter a name that says where the key is used (e.g.
Production · web). - Choose the environment and scope.
- (Optional) add an IP allowlist.
- Click Create.
The full token is displayed once, immediately after creation. Copy it and store it somewhere safe — typically an environment variable or a secrets manager. It is never shown again.
Creating, rotating and revoking keys requires the admin workspace role.
Managing keys
The keys table shows each key's name, masked value, environment, scope, creation date, last-used time and total request count. For each key you can:
- Rotate — issue a brand-new token and revoke the old one. Use this on a schedule, or immediately if a key may have leaked. Update your application with the new token; the old one stops working at once.
- Revoke — permanently disable the key. Requests using it will fail.
- Edit the IP allowlist — tighten or loosen the allowed ranges.
All of these actions are recorded in the Audit log.
If a key leaks
- Rotate or revoke it immediately — don't wait.
- Deploy the new token to your application.
- Review the Audit log and Metrics for unexpected activity.
Next
See the v1 API reference for every endpoint, or API & SDK for an integration guide with examples.